Hello everyone, I'm a new user here.
Yesterday I noticed something consuming my CPUs resources, and I found this COM surrogate process running in my task menager.
I googled it and I stumbled upon this forum and 2 topics by people with the same problem who got help from Mr. Broni.
I'm pasting the FRST log file with addition, hopefully you guys, or Mr. Broni have time to guide me through the removal process.
Thank you.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-07-2017
Ran by Korisnik (administrator) on MSIGT60 (02-07-2017 23:09:52)
Running from C:\Users\Roko\AppData\Local\Temp\scoped_dir5484_781
Loaded Profiles: Korisnik (Available Profiles: Korisnik)
Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18290688 2017-03-30] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3366624 2016-12-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [297984 2016-01-22] (MSI)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2017-04-13] (Razer Inc.)
HKLM-x32\...\Run: [KLM] => C:\Program Files (x86)\KLM\KLM.exe [2151224 2015-11-10] (Application)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-1483072306-4082277022-3870291831-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [170360 2017-04-01] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2017-04-01] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4F116F40-EBFC-4D9D-9F6E-D4ECEE7223D9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BC1B9C2D-5EC3-4230-9CAC-826EEAD2C223}: [DhcpNameServer] 83.139.103.3 83.139.121.8
Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-07] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-07] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-07] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
Opera:
=======
OPR Extension: (Adblock Plus) - C:\Users\Roko\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2017-05-07]
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144088 2016-12-22] (ELAN Microelectronics Corp.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2016-01-22] (Micro-Star International Co., Ltd.) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-04-01] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation)
S2 NVWMI; C:\Windows\system32\nvwmi64.exe [4243392 2017-04-01] (NVIDIA Corporation)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [401024 2017-06-16] (Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [178824 2017-06-16] (Razer Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [32840 2017-02-10] (ELAN Microelectronic Corp.)
R3 KillerEth; C:\Windows\system32\DRIVERS\e2xw8x64.sys [162456 2016-02-12] (Qualcomm Atheros, Inc.)
R1 MpKsl0a861aa9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A48DACBD-A7AD-49D8-8C9D-767C16EB79A6}\MpKsl0a861aa9.sys [44928 2017-07-02] (Microsoft Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57976 2017-04-26] (NVIDIA Corporation)
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [51736 2016-06-22] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-10-08] (Razer, Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-02] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-02 23:08 - 2017-07-02 23:09 - 00000000 ____D C:\FRST
2017-07-02 23:08 - 2017-07-02 23:08 - 02435584 _____ (Farbar) C:\Users\Roko\Desktop\FRST64.exe
2017-07-02 23:05 - 2017-07-02 23:05 - 00000906 _____ C:\Users\Roko\Desktop\JRT.txt
2017-07-02 23:04 - 2017-07-02 23:04 - 01663672 _____ (Malwarebytes) C:\Users\Roko\Desktop\JRT.exe
2017-07-02 23:00 - 2017-07-02 23:00 - 00001153 _____ C:\Users\Roko\Desktop\AdwCleaner[C2].txt
2017-07-02 22:13 - 2017-07-02 22:13 - 04110280 _____ C:\Users\Roko\Desktop\adwcleaner_6.047.exe
2017-07-02 16:06 - 2017-07-02 16:02 - 00002116 _____ C:\Users\Roko\Desktop\mbar-log-2017-07-02 (15-48-53).txt
2017-07-02 15:48 - 2017-07-02 16:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-07-02 15:46 - 2017-07-02 15:46 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-07-02 15:43 - 2017-07-02 16:02 - 00000000 ____D C:\Users\Roko\Desktop\mbar
2017-07-02 15:42 - 2017-07-02 15:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Roko\Desktop\mbar-1.09.3.1001.exe
2017-07-02 15:08 - 2017-07-02 15:08 - 00004256 _____ C:\Users\Roko\Desktop\rk_DF55.tmp.txt
2017-07-02 14:45 - 2017-07-02 14:45 - 00000870 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-07-02 14:45 - 2017-07-02 14:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-02 14:45 - 2017-07-02 14:45 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-02 14:43 - 2017-07-02 14:43 - 35489760 _____ (Adlice Software ) C:\Users\Roko\Desktop\RogueKiller_setup.exe
2017-07-02 14:40 - 2017-07-02 14:46 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-07-02 14:34 - 2017-07-02 14:39 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-02 14:30 - 2017-07-02 14:31 - 35489760 _____ (Adlice Software ) C:\Users\Roko\Downloads\RogueKiller_setup_ref3.exe
2017-07-02 14:14 - 2017-07-02 22:56 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-07-02 14:14 - 2017-07-02 14:14 - 00001883 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-02 14:14 - 2017-07-02 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-02 14:14 - 2017-07-02 14:14 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-02 14:14 - 2017-06-27 12:06 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-07-02 14:11 - 2017-07-02 14:13 - 65033984 _____ (Malwarebytes ) C:\Users\Roko\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-07-02 14:08 - 2017-07-02 14:10 - 64025992 _____ (Malwarebytes ) C:\Users\Roko\Desktop\mb3-setup-32138.32138-3.1.2.1733-1.0.139-1.0.2060.exe
2017-07-02 11:40 - 2017-07-02 11:40 - 00000000 ____D C:\Users\Roko\Downloads\La.Haine.French.Dutch.and.English.Subs.Dvdrip.1995-PrinzNL
2017-06-30 23:04 - 2017-06-30 23:04 - 00001021 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-06-29 23:53 - 2017-06-29 23:53 - 00003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-06-29 23:53 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-06-29 23:53 - 2017-06-21 09:07 - 00179320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-06-29 23:53 - 2017-06-21 09:07 - 00146552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-06-29 23:53 - 2017-06-21 09:07 - 00048248 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-06-28 19:39 - 2017-06-28 19:39 - 00000000 ____D C:\Users\Roko\Documents\League of Legends
2017-06-28 19:38 - 2017-06-28 19:38 - 00000000 ____D C:\Users\Roko\AppData\Roaming\LolClient
2017-06-28 18:04 - 2017-06-28 18:04 - 00000000 ____D C:\ProgramData\Riot Games
2017-06-28 18:03 - 2017-06-29 10:39 - 00001720 _____ C:\Users\Public\Desktop\League of Legends.lnk
2017-06-28 18:03 - 2017-06-28 18:03 - 00000000 ____D C:\Riot Games
2017-06-28 18:03 - 2017-06-28 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2017-06-28 18:03 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2017-06-28 18:03 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2017-06-28 18:03 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2017-06-28 18:00 - 2017-06-28 18:03 - 00000000 ____D C:\Users\Roko\AppData\Roaming\Riot Games
2017-06-22 10:05 - 2017-07-02 15:48 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-21 21:14 - 2017-06-21 21:14 - 00000000 ____D C:\Users\Roko\Desktop\YEEZY
2017-06-20 18:32 - 2017-06-20 18:42 - 00000000 ____D C:\Users\Roko\Downloads\Rushmore (1998)
2017-06-20 18:32 - 2017-06-20 18:33 - 00000000 ____D C:\Users\Roko\Downloads\Leon The Professional Extended (1994)
2017-06-20 18:32 - 2017-06-20 18:32 - 00018076 _____ C:\Users\Roko\Downloads\Léon- The Professional (1994) [720p] [YTS.AG].torrent
2017-06-20 18:32 - 2017-06-20 18:32 - 00008188 _____ C:\Users\Roko\Downloads\Rushmore (1998) [720p] [YTS.AG] (1).torrent
2017-06-20 18:31 - 2017-06-20 18:31 - 00008188 _____ C:\Users\Roko\Downloads\Rushmore (1998) [720p] [YTS.AG].torrent
2017-06-17 17:25 - 2017-06-29 15:57 - 00000000 ____D C:\Users\Roko\AppData\Roaming\TS3Client
2017-06-17 17:25 - 2017-06-17 17:25 - 00000979 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2017-06-17 17:25 - 2017-06-17 17:25 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2017-06-17 17:25 - 2017-06-17 17:25 - 00000000 ____D C:\Users\Roko\.TeamSpeak 3
2017-06-17 17:25 - 2017-06-17 17:25 - 00000000 ____D C:\Users\Roko\.QtWebEngineProcess
2017-06-17 17:25 - 2017-06-17 17:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2017-06-16 10:06 - 2017-06-16 10:06 - 00109696 _____ (Razer Inc.) C:\Windows\system32\RzChromaSDK64.dll
2017-06-16 10:06 - 2017-06-16 10:06 - 00102016 _____ (Razer Inc.) C:\Windows\SysWOW64\RzChromaSDK.dll
2017-06-16 09:54 - 2017-06-16 09:54 - 00049288 _____ (Razer Inc.) C:\Windows\SysWOW64\RzAPIChromaSDK.dll
2017-06-15 23:33 - 2017-06-15 23:33 - 325541992 _____ C:\Windows\MEMORY.DMP
2017-06-15 23:33 - 2017-06-15 23:33 - 00270816 _____ C:\Windows\Minidump\061517-17265-01.dmp
2017-06-14 16:39 - 2017-06-02 14:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-06-14 16:39 - 2017-06-02 14:12 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-06-14 16:39 - 2017-06-02 14:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-06-14 16:39 - 2017-06-02 14:06 - 01001984 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-06-14 16:39 - 2017-06-02 14:01 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-06-14 16:39 - 2017-06-02 13:30 - 03635200 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-06-14 16:39 - 2017-06-02 13:03 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-06-14 16:39 - 2017-06-02 12:58 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-06-14 16:39 - 2017-06-02 12:25 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-06-14 16:39 - 2017-06-02 12:24 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-06-14 16:39 - 2017-06-02 12:17 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-06-14 16:39 - 2017-06-02 12:02 - 02751488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-06-14 16:39 - 2017-06-02 11:43 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-06-14 16:39 - 2017-06-02 11:43 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-06-14 16:39 - 2017-05-15 21:58 - 00121184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys
2017-06-14 16:39 - 2017-05-14 22:44 - 04170240 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-06-14 16:39 - 2017-05-14 22:42 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-06-14 16:39 - 2017-05-14 22:26 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-06-14 16:39 - 2017-05-14 22:19 - 25738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-06-14 16:39 - 2017-05-14 22:19 - 01364040 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-06-14 16:39 - 2017-05-14 22:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-06-14 16:39 - 2017-05-14 21:55 - 05975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-06-14 16:39 - 2017-05-14 21:32 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2017-06-14 16:39 - 2017-05-14 21:31 - 01033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-06-14 16:39 - 2017-05-14 21:22 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-06-14 16:39 - 2017-05-14 21:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-06-14 16:39 - 2017-05-14 21:11 - 20274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-06-14 16:39 - 2017-05-14 21:10 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-06-14 16:39 - 2017-05-14 21:04 - 00315224 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-06-14 16:39 - 2017-05-14 21:03 - 00373080 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-06-14 16:39 - 2017-05-14 20:54 - 15252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-06-14 16:39 - 2017-05-14 20:52 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-06-14 16:39 - 2017-05-14 20:48 - 05274112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2017-06-14 16:39 - 2017-05-14 20:46 - 00880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-06-14 16:39 - 2017-05-14 20:44 - 04549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-06-14 16:39 - 2017-05-14 20:40 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-06-14 16:39 - 2017-05-14 20:38 - 07796736 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-06-14 16:39 - 2017-05-14 20:37 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-06-14 16:39 - 2017-05-14 20:30 - 13664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-06-14 16:39 - 2017-05-14 20:27 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-06-14 16:39 - 2017-05-14 20:16 - 05268992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-06-14 16:39 - 2017-05-14 20:15 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-06-14 16:39 - 2017-05-14 20:13 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-06-14 16:39 - 2017-05-14 20:11 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-06-14 16:39 - 2017-05-14 20:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-06-14 16:39 - 2017-05-14 20:06 - 07441240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-06-14 16:39 - 2017-05-14 20:06 - 01737600 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-06-14 16:39 - 2017-05-14 20:06 - 01502000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-06-14 16:39 - 2017-05-12 19:05 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-06-14 16:39 - 2017-05-12 18:16 - 01084928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-06-14 16:39 - 2017-05-12 18:13 - 01559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-06-14 16:39 - 2017-05-12 17:51 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-06-14 16:39 - 2017-05-12 17:50 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-06-14 16:39 - 2017-05-12 17:48 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-06-14 16:39 - 2017-05-12 17:47 - 00726528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-06-14 16:39 - 2017-05-12 06:10 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-06-14 16:39 - 2017-05-12 04:58 - 01985536 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-06-14 16:39 - 2017-05-12 04:48 - 01377792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-06-14 16:39 - 2017-05-12 04:18 - 03714560 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-06-14 16:39 - 2017-05-12 04:11 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-06-14 16:39 - 2017-05-12 04:10 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-06-14 16:39 - 2017-05-12 04:07 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2017-06-14 16:39 - 2017-05-12 04:06 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-06-14 16:39 - 2017-05-12 04:04 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-06-14 16:39 - 2017-05-12 04:00 - 02240512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-06-14 16:39 - 2017-05-12 01:36 - 22361848 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-06-14 16:39 - 2017-05-12 01:32 - 19788672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-06-14 16:39 - 2017-05-10 20:19 - 00101720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-06-14 16:39 - 2017-05-06 18:05 - 01094656 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-06-14 16:39 - 2017-05-06 18:04 - 00865792 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-06-14 16:39 - 2017-04-09 22:40 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winhvr.sys
2017-06-14 16:39 - 2017-04-09 22:39 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmclr.sys
2017-06-14 16:39 - 2017-04-09 22:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbusr.sys
2017-06-14 16:39 - 2017-04-09 21:00 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\vmbuspiper.dll
2017-06-14 16:39 - 2017-04-06 19:37 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-06-14 16:39 - 2017-04-06 19:16 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2017-06-14 16:39 - 2017-04-06 18:50 - 01436672 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-06-14 16:39 - 2017-04-06 18:46 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-06-14 16:39 - 2017-04-06 18:46 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-06-14 16:39 - 2017-04-06 18:35 - 01362432 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2017-06-14 16:39 - 2017-04-06 18:15 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-06-14 16:39 - 2017-04-06 17:44 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2017-06-14 16:39 - 2017-04-02 16:49 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2017-06-14 16:39 - 2017-04-02 15:40 - 02013016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-06-14 16:39 - 2016-06-11 18:50 - 00987136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-06-14 16:39 - 2016-06-11 18:24 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-06-10 09:16 - 2017-06-10 09:16 - 00013216 _____ C:\Users\Roko\Documents\cc_20170610_091604.reg
2017-06-10 09:15 - 2017-06-10 09:15 - 00067434 _____ C:\Users\Roko\Documents\cc_20170610_091534.reg
2017-06-07 22:57 - 2017-06-07 23:04 - 00000000 ____D C:\Users\Roko\Downloads\The Last King of Scotland (2006)
2017-06-04 09:46 - 2017-06-04 09:53 - 00000000 ____D C:\Users\Roko\Desktop\New folder
2017-06-04 09:00 - 2017-06-04 09:07 - 00007602 _____ C:\Users\Roko\AppData\Local\resmon.resmoncfg
2017-06-04 07:44 - 2017-07-02 22:55 - 00000000 ____D C:\AdwCleaner
2017-06-03 09:13 - 2017-06-03 10:40 - 00000000 ____D C:\Users\Roko\Downloads\codex-rime
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-02 23:05 - 2017-05-06 20:57 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-02 23:03 - 2017-05-06 20:54 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1483072306-4082277022-3870291831-1001
2017-07-02 22:58 - 2017-05-07 01:07 - 00000000 ____D C:\Program Files (x86)\Steam
2017-07-02 22:56 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-02 22:55 - 2017-05-06 20:44 - 00000000 ____D C:\Users\Roko
2017-07-02 15:06 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-07-02 14:38 - 2017-05-06 20:55 - 00000000 ____D C:\Users\Roko\AppData\Roaming\uTorrent
2017-07-02 14:03 - 2017-05-06 21:07 - 00000000 ____D C:\Program Files\Opera
2017-07-02 02:09 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf
2017-06-30 23:04 - 2017-05-06 21:07 - 00003832 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1494097665
2017-06-29 23:53 - 2017-05-06 23:11 - 00003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:11 - 00001432 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-06-29 23:53 - 2017-05-06 23:10 - 00004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 20:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-06-29 23:53 - 2017-05-06 20:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-06-29 23:53 - 2017-05-06 20:57 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-06-21 09:07 - 2017-05-06 23:11 - 01903224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 01755256 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 01489528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 01317496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 00121464 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2017-06-20 22:58 - 2017-05-06 23:10 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-06-17 03:31 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2017-06-16 21:09 - 2017-05-06 20:48 - 00000000 ____D C:\Users\Roko\AppData\Local\Packages
2017-06-16 21:09 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-16 21:09 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2017-06-15 23:33 - 2017-05-15 20:24 - 00000000 ____D C:\Windows\Minidump
2017-06-15 09:25 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2017-06-15 08:10 - 2013-08-22 16:44 - 00365880 _____ C:\Windows\system32\FNTCACHE.DAT
2017-06-15 00:45 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2017-06-14 17:01 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2017-06-14 17:00 - 2017-05-06 21:13 - 00000000 ____D C:\Windows\system32\MRT
2017-06-14 16:58 - 2017-05-06 21:13 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-06-14 16:34 - 2017-05-07 14:49 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-06-14 16:34 - 2017-05-07 14:49 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-06-14 16:34 - 2017-05-07 14:49 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-06-13 21:39 - 2017-05-10 00:17 - 00000980 _____ C:\Users\Roko\Documents\fgfgfgffg.txt
2017-06-13 21:10 - 2017-06-01 19:42 - 00000000 ____D C:\Users\Roko\Desktop\TRIO DIvertimento
2017-06-10 10:20 - 2017-05-06 21:08 - 00000000 ____D C:\Users\Roko\AppData\Local\CrashDumps
2017-06-10 10:18 - 2017-05-06 23:02 - 00000000 ____D C:\Users\Roko\AppData\Local\ElevatedDiagnostics
2017-06-10 10:06 - 2017-05-06 20:46 - 00818732 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-10 09:27 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-06-10 09:22 - 2017-05-15 21:51 - 00035328 ___SH C:\Users\Roko\Desktop\Thumbs.db
2017-06-10 09:14 - 2017-05-07 06:36 - 00000000 ____D C:\Windows\Panther
2017-06-10 09:07 - 2017-05-07 05:50 - 00000000 __SHD C:\Users\Roko\AppData\Local\EmieUserList
2017-06-10 09:07 - 2017-05-07 05:50 - 00000000 __SHD C:\Users\Roko\AppData\Local\EmieSiteList
2017-06-10 09:06 - 2017-05-08 22:18 - 00004478 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-06-10 09:06 - 2017-05-07 22:12 - 00000000 ____D C:\Users\Roko\AppData\Local\Adobe
2017-06-10 09:06 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-10 09:06 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-07 22:51 - 2017-05-06 20:57 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-06-04 09:10 - 2013-08-22 17:36 - 00000000 ____D C:\PerfLogs
2017-06-03 04:31 - 2017-05-09 16:24 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-03 04:31 - 2017-05-09 16:24 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2017-06-04 09:00 - 2017-06-04 09:07 - 0007602 _____ () C:\Users\Roko\AppData\Local\resmon.resmoncfg
2017-05-25 22:06 - 2017-05-25 22:06 - 0000003 _____ () C:\Users\Roko\AppData\Local\updater.log
2017-05-25 22:06 - 2017-05-25 22:06 - 0000425 _____ () C:\Users\Roko\AppData\Local\UserProducts.xml
Files to move or delete:
====================
C:\Users\Roko\installshield_scm.reg
C:\Users\Roko\scm.reg
Some files in TEMP:
====================
2017-07-02 14:34 - 2017-05-14 20:06 - 1737600 _____ (Microsoft Corporation) C:\Users\Roko\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-25 20:27
==================== End of FRST.txt ============================
Yesterday I noticed something consuming my CPUs resources, and I found this COM surrogate process running in my task menager.
I googled it and I stumbled upon this forum and 2 topics by people with the same problem who got help from Mr. Broni.
I'm pasting the FRST log file with addition, hopefully you guys, or Mr. Broni have time to guide me through the removal process.
Thank you.
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 02-07-2017
Ran by Korisnik (administrator) on MSIGT60 (02-07-2017 23:09:52)
Running from C:\Users\Roko\AppData\Local\Temp\scoped_dir5484_781
Loaded Profiles: Korisnik (Available Profiles: Korisnik)
Platform: Windows 8.1 Pro (Update) (X64) Language: English (United States)
Internet Explorer Version 11 (Default browser: Opera)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool:
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Intel Corporation) C:\Windows\System32\igfxCUIService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Micro-Star International Co., Ltd.) C:\Program Files (x86)\SCM\MSIService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe
(Razer Inc.) C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe
() C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
(Motorola Solutions, Inc.) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NvContainer\nvcontainer.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
==================== Registry (Whitelisted) ====================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [ShadowPlay] => "C:\Windows\system32\rundll32.exe" C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [18290688 2017-03-30] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [3366624 2016-12-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [BTMTrayAgent] => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll",TrayApp
HKLM\...\Run: [SCM] => C:\Program Files (x86)\SCM\SCM.exe [297984 2016-01-22] (MSI)
HKLM\...\Run: [WindowsDefender] => "%ProgramFiles%\Windows Defender\MSASCuiL.exe"
HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [3146704 2017-05-09] (Malwarebytes)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [587288 2017-03-15] (Oracle Corporation)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [596640 2017-04-13] (Razer Inc.)
HKLM-x32\...\Run: [KLM] => C:\Program Files (x86)\KLM\KLM.exe [2151224 2015-11-10] (Application)
HKLM-x32\...\Run: [Lightshot] => C:\Program Files (x86)\Skillbrains\lightshot\Lightshot.exe [225944 2017-04-11] ()
Winlogon\Notify\igfxcui: igfxdev.dll [X]
HKU\S-1-5-21-1483072306-4082277022-3870291831-1001\...\Run: [Steam] => C:\Program Files (x86)\Steam\steam.exe [3042592 2017-06-08] (Valve Corporation)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [170360 2017-04-01] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [148016 2017-04-01] (NVIDIA Corporation)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{4F116F40-EBFC-4D9D-9F6E-D4ECEE7223D9}: [DhcpNameServer] 192.168.1.1
Tcpip\..\Interfaces\{BC1B9C2D-5EC3-4230-9CAC-826EEAD2C223}: [DhcpNameServer] 83.139.103.3 83.139.121.8
Internet Explorer:
==================
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_131\bin\ssv.dll [2017-05-07] (Oracle Corporation)
BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_131\bin\jp2ssv.dll [2017-05-07] (Oracle Corporation)
BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
FireFox:
========
FF Plugin: @java.com/DTPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\dtplugin\npDeployJava1.dll [2017-05-07] (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.131.2 -> C:\Program Files\Java\jre1.8.0_131\bin\plugin2\npjp2.dll [2017-05-07] (Oracle Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
Opera:
=======
OPR Extension: (Adblock Plus) - C:\Users\Roko\AppData\Roaming\Opera Software\Opera Stable\Extensions\oidhhegpmlfpoeialbgcdocjalghfpkp [2017-05-07]
StartMenuInternet: (HKLM) OperaStable - C:\Program Files\Opera\Launcher.exe
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [144088 2016-12-22] (ELAN Microelectronics Corp.)
R2 igfxCUIService1.0.0.0; C:\Windows\system32\igfxCUIService.exe [330136 2015-08-27] (Intel Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4470736 2017-05-09] (Malwarebytes)
R2 Micro Star SCM; C:\Program Files (x86)\SCM\MSIService.exe [160768 2016-01-22] (Micro-Star International Co., Ltd.) [File not signed]
R2 NvContainerLocalSystem; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
S3 NvContainerNetworkService; C:\Program Files\NVIDIA Corporation\NvContainer\nvcontainer.exe [495224 2017-06-21] (NVIDIA Corporation)
R2 NVDisplay.ContainerLocalSystem; C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe [462784 2017-04-01] (NVIDIA Corporation)
R2 NvTelemetryContainer; C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe [450168 2017-06-21] (NVIDIA Corporation)
S2 NVWMI; C:\Windows\system32\nvwmi64.exe [4243392 2017-04-01] (NVIDIA Corporation)
R2 Razer Chroma SDK Server; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKServer.exe [401024 2017-06-16] (Razer Inc.)
R2 Razer Chroma SDK Service; C:\Program Files (x86)\Razer Chroma SDK\bin\RzSDKService.exe [178824 2017-06-16] (Razer Inc.)
R2 Razer Game Scanner Service; C:\Program Files (x86)\Razer\Razer Services\GSS\GameScannerService.exe [189264 2016-09-25] ()
R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [361824 2017-01-12] (Microsoft Corporation)
R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [119872 2017-01-12] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
S3 btmaux; C:\Windows\system32\DRIVERS\btmaux.sys [121728 2012-08-27] (Motorola Solutions, Inc.)
R3 btmhsf; C:\Windows\system32\DRIVERS\btmhsf.sys [857472 2012-08-29] (Motorola Solutions, Inc.)
R3 ETDSMBus; C:\Windows\System32\drivers\ETDSMBus.sys [32840 2017-02-10] (ELAN Microelectronic Corp.)
R3 KillerEth; C:\Windows\system32\DRIVERS\e2xw8x64.sys [162456 2016-02-12] (Qualcomm Atheros, Inc.)
R1 MpKsl0a861aa9; C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{A48DACBD-A7AD-49D8-8C9D-767C16EB79A6}\MpKsl0a861aa9.sys [44928 2017-07-02] (Microsoft Corporation)
R3 NETwNe64; C:\Windows\system32\DRIVERS\NETwew00.sys [3345376 2013-09-04] (Intel Corporation)
S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [30328 2017-06-21] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\system32\drivers\nvvad64v.sys [48248 2017-06-21] (NVIDIA Corporation)
R3 nvvhci; C:\Windows\System32\drivers\nvvhci.sys [57976 2017-04-26] (NVIDIA Corporation)
R3 rzendpt; C:\Windows\System32\drivers\rzendpt.sys [51736 2016-06-22] (Razer Inc)
R2 rzpmgrk; C:\Windows\system32\drivers\rzpmgrk.sys [44144 2016-09-17] (Razer, Inc.)
R2 rzpnk; C:\Windows\system32\drivers\rzpnk.sys [137840 2016-10-08] (Razer, Inc.)
U3 TrueSight; C:\Windows\System32\drivers\TrueSight.sys [28272 2017-07-02] ()
S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [46600 2017-02-10] (Microsoft Corporation)
R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [274776 2017-01-12] (Microsoft Corporation)
R3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [117592 2017-01-12] (Microsoft Corporation)
S3 MBAMWebProtection; \??\C:\Windows\system32\drivers\mwac.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-02 23:08 - 2017-07-02 23:09 - 00000000 ____D C:\FRST
2017-07-02 23:08 - 2017-07-02 23:08 - 02435584 _____ (Farbar) C:\Users\Roko\Desktop\FRST64.exe
2017-07-02 23:05 - 2017-07-02 23:05 - 00000906 _____ C:\Users\Roko\Desktop\JRT.txt
2017-07-02 23:04 - 2017-07-02 23:04 - 01663672 _____ (Malwarebytes) C:\Users\Roko\Desktop\JRT.exe
2017-07-02 23:00 - 2017-07-02 23:00 - 00001153 _____ C:\Users\Roko\Desktop\AdwCleaner[C2].txt
2017-07-02 22:13 - 2017-07-02 22:13 - 04110280 _____ C:\Users\Roko\Desktop\adwcleaner_6.047.exe
2017-07-02 16:06 - 2017-07-02 16:02 - 00002116 _____ C:\Users\Roko\Desktop\mbar-log-2017-07-02 (15-48-53).txt
2017-07-02 15:48 - 2017-07-02 16:03 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2017-07-02 15:46 - 2017-07-02 15:46 - 00109272 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys
2017-07-02 15:43 - 2017-07-02 16:02 - 00000000 ____D C:\Users\Roko\Desktop\mbar
2017-07-02 15:42 - 2017-07-02 15:42 - 16563352 _____ (Malwarebytes Corp.) C:\Users\Roko\Desktop\mbar-1.09.3.1001.exe
2017-07-02 15:08 - 2017-07-02 15:08 - 00004256 _____ C:\Users\Roko\Desktop\rk_DF55.tmp.txt
2017-07-02 14:45 - 2017-07-02 14:45 - 00000870 _____ C:\Users\Public\Desktop\RogueKiller.lnk
2017-07-02 14:45 - 2017-07-02 14:45 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\RogueKiller
2017-07-02 14:45 - 2017-07-02 14:45 - 00000000 ____D C:\Program Files\RogueKiller
2017-07-02 14:43 - 2017-07-02 14:43 - 35489760 _____ (Adlice Software ) C:\Users\Roko\Desktop\RogueKiller_setup.exe
2017-07-02 14:40 - 2017-07-02 14:46 - 00028272 _____ C:\Windows\system32\Drivers\TrueSight.sys
2017-07-02 14:34 - 2017-07-02 14:39 - 00000000 ____D C:\ProgramData\RogueKiller
2017-07-02 14:30 - 2017-07-02 14:31 - 35489760 _____ (Adlice Software ) C:\Users\Roko\Downloads\RogueKiller_setup_ref3.exe
2017-07-02 14:14 - 2017-07-02 22:56 - 00253856 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2017-07-02 14:14 - 2017-07-02 14:14 - 00001883 _____ C:\Users\Public\Desktop\Malwarebytes.lnk
2017-07-02 14:14 - 2017-07-02 14:14 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes
2017-07-02 14:14 - 2017-07-02 14:14 - 00000000 ____D C:\Program Files\Malwarebytes
2017-07-02 14:14 - 2017-06-27 12:06 - 00077376 _____ C:\Windows\system32\Drivers\mbae64.sys
2017-07-02 14:11 - 2017-07-02 14:13 - 65033984 _____ (Malwarebytes ) C:\Users\Roko\Desktop\mb3-setup-consumer-3.1.2.1733-1.0.160-1.0.2251.exe
2017-07-02 14:08 - 2017-07-02 14:10 - 64025992 _____ (Malwarebytes ) C:\Users\Roko\Desktop\mb3-setup-32138.32138-3.1.2.1733-1.0.139-1.0.2060.exe
2017-07-02 11:40 - 2017-07-02 11:40 - 00000000 ____D C:\Users\Roko\Downloads\La.Haine.French.Dutch.and.English.Subs.Dvdrip.1995-PrinzNL
2017-06-30 23:04 - 2017-06-30 23:04 - 00001021 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Opera Browser.lnk
2017-06-29 23:53 - 2017-06-29 23:53 - 00003814 _____ C:\Windows\System32\Tasks\NVIDIA GeForce Experience SelfUpdate_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-06-29 23:53 - 00000000 ____D C:\Windows\LastGood.Tmp
2017-06-29 23:53 - 2017-06-21 09:07 - 00179320 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap64v.dll
2017-06-29 23:53 - 2017-06-21 09:07 - 00146552 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvaudcap32v.dll
2017-06-29 23:53 - 2017-06-21 09:07 - 00048248 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad64v.sys
2017-06-28 19:39 - 2017-06-28 19:39 - 00000000 ____D C:\Users\Roko\Documents\League of Legends
2017-06-28 19:38 - 2017-06-28 19:38 - 00000000 ____D C:\Users\Roko\AppData\Roaming\LolClient
2017-06-28 18:04 - 2017-06-28 18:04 - 00000000 ____D C:\ProgramData\Riot Games
2017-06-28 18:03 - 2017-06-29 10:39 - 00001720 _____ C:\Users\Public\Desktop\League of Legends.lnk
2017-06-28 18:03 - 2017-06-28 18:03 - 00000000 ____D C:\Riot Games
2017-06-28 18:03 - 2017-06-28 18:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Legends
2017-06-28 18:03 - 2008-07-12 08:18 - 03851784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DX9_39.dll
2017-06-28 18:03 - 2008-07-12 08:18 - 01493528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\D3DCompiler_39.dll
2017-06-28 18:03 - 2008-07-12 08:18 - 00467984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3dx10_39.dll
2017-06-28 18:00 - 2017-06-28 18:03 - 00000000 ____D C:\Users\Roko\AppData\Roaming\Riot Games
2017-06-22 10:05 - 2017-07-02 15:48 - 00000000 ____D C:\ProgramData\Malwarebytes
2017-06-21 21:14 - 2017-06-21 21:14 - 00000000 ____D C:\Users\Roko\Desktop\YEEZY
2017-06-20 18:32 - 2017-06-20 18:42 - 00000000 ____D C:\Users\Roko\Downloads\Rushmore (1998)
2017-06-20 18:32 - 2017-06-20 18:33 - 00000000 ____D C:\Users\Roko\Downloads\Leon The Professional Extended (1994)
2017-06-20 18:32 - 2017-06-20 18:32 - 00018076 _____ C:\Users\Roko\Downloads\Léon- The Professional (1994) [720p] [YTS.AG].torrent
2017-06-20 18:32 - 2017-06-20 18:32 - 00008188 _____ C:\Users\Roko\Downloads\Rushmore (1998) [720p] [YTS.AG] (1).torrent
2017-06-20 18:31 - 2017-06-20 18:31 - 00008188 _____ C:\Users\Roko\Downloads\Rushmore (1998) [720p] [YTS.AG].torrent
2017-06-17 17:25 - 2017-06-29 15:57 - 00000000 ____D C:\Users\Roko\AppData\Roaming\TS3Client
2017-06-17 17:25 - 2017-06-17 17:25 - 00000979 _____ C:\Users\Public\Desktop\TeamSpeak 3 Client.lnk
2017-06-17 17:25 - 2017-06-17 17:25 - 00000941 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamSpeak 3 Client.lnk
2017-06-17 17:25 - 2017-06-17 17:25 - 00000000 ____D C:\Users\Roko\.TeamSpeak 3
2017-06-17 17:25 - 2017-06-17 17:25 - 00000000 ____D C:\Users\Roko\.QtWebEngineProcess
2017-06-17 17:25 - 2017-06-17 17:25 - 00000000 ____D C:\Program Files\TeamSpeak 3 Client
2017-06-16 10:06 - 2017-06-16 10:06 - 00109696 _____ (Razer Inc.) C:\Windows\system32\RzChromaSDK64.dll
2017-06-16 10:06 - 2017-06-16 10:06 - 00102016 _____ (Razer Inc.) C:\Windows\SysWOW64\RzChromaSDK.dll
2017-06-16 09:54 - 2017-06-16 09:54 - 00049288 _____ (Razer Inc.) C:\Windows\SysWOW64\RzAPIChromaSDK.dll
2017-06-15 23:33 - 2017-06-15 23:33 - 325541992 _____ C:\Windows\MEMORY.DMP
2017-06-15 23:33 - 2017-06-15 23:33 - 00270816 _____ C:\Windows\Minidump\061517-17265-01.dmp
2017-06-14 16:39 - 2017-06-02 14:15 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\SearchProtocolHost.exe
2017-06-14 16:39 - 2017-06-02 14:12 - 00468992 _____ (Microsoft Corporation) C:\Windows\system32\mssph.dll
2017-06-14 16:39 - 2017-06-02 14:12 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\mssphtb.dll
2017-06-14 16:39 - 2017-06-02 14:06 - 01001984 _____ (Microsoft Corporation) C:\Windows\HelpPane.exe
2017-06-14 16:39 - 2017-06-02 14:01 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\mssvp.dll
2017-06-14 16:39 - 2017-06-02 13:30 - 03635200 _____ (Microsoft Corporation) C:\Windows\system32\tquery.dll
2017-06-14 16:39 - 2017-06-02 13:03 - 00903168 _____ (Microsoft Corporation) C:\Windows\system32\SearchIndexer.exe
2017-06-14 16:39 - 2017-06-02 12:58 - 02551808 _____ (Microsoft Corporation) C:\Windows\system32\mssrch.dll
2017-06-14 16:39 - 2017-06-02 12:25 - 00272896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchProtocolHost.exe
2017-06-14 16:39 - 2017-06-02 12:24 - 00391680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssph.dll
2017-06-14 16:39 - 2017-06-02 12:17 - 00699392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssvp.dll
2017-06-14 16:39 - 2017-06-02 12:02 - 02751488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tquery.dll
2017-06-14 16:39 - 2017-06-02 11:43 - 01920000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mssrch.dll
2017-06-14 16:39 - 2017-06-02 11:43 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SearchIndexer.exe
2017-06-14 16:39 - 2017-05-15 21:58 - 00121184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tm.sys
2017-06-14 16:39 - 2017-05-14 22:44 - 04170240 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2017-06-14 16:39 - 2017-05-14 22:42 - 00107520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tdx.sys
2017-06-14 16:39 - 2017-05-14 22:26 - 00576512 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2017-06-14 16:39 - 2017-05-14 22:19 - 25738752 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2017-06-14 16:39 - 2017-05-14 22:19 - 01364040 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll
2017-06-14 16:39 - 2017-05-14 22:10 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2017-06-14 16:39 - 2017-05-14 21:55 - 05975040 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2017-06-14 16:39 - 2017-05-14 21:32 - 07077376 _____ (Microsoft Corporation) C:\Windows\system32\glcndFilter.dll
2017-06-14 16:39 - 2017-05-14 21:31 - 01033216 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll
2017-06-14 16:39 - 2017-05-14 21:22 - 00499200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2017-06-14 16:39 - 2017-05-14 21:19 - 00806912 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2017-06-14 16:39 - 2017-05-14 21:11 - 20274688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2017-06-14 16:39 - 2017-05-14 21:10 - 00663552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2017-06-14 16:39 - 2017-05-14 21:04 - 00315224 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\atmfd.dll
2017-06-14 16:39 - 2017-05-14 21:03 - 00373080 _____ (Adobe Systems Incorporated) C:\Windows\system32\atmfd.dll
2017-06-14 16:39 - 2017-05-14 20:54 - 15252992 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2017-06-14 16:39 - 2017-05-14 20:52 - 03240960 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2017-06-14 16:39 - 2017-05-14 20:48 - 05274112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\glcndFilter.dll
2017-06-14 16:39 - 2017-05-14 20:46 - 00880640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcomm.dll
2017-06-14 16:39 - 2017-05-14 20:44 - 04549120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2017-06-14 16:39 - 2017-05-14 20:40 - 00693248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2017-06-14 16:39 - 2017-05-14 20:38 - 07796736 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Data.Pdf.dll
2017-06-14 16:39 - 2017-05-14 20:37 - 01544704 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2017-06-14 16:39 - 2017-05-14 20:30 - 13664768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2017-06-14 16:39 - 2017-05-14 20:27 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2017-06-14 16:39 - 2017-05-14 20:16 - 05268992 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.Data.Pdf.dll
2017-06-14 16:39 - 2017-05-14 20:15 - 02767872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2017-06-14 16:39 - 2017-05-14 20:13 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2017-06-14 16:39 - 2017-05-14 20:11 - 01314816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2017-06-14 16:39 - 2017-05-14 20:11 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2017-06-14 16:39 - 2017-05-14 20:06 - 07441240 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2017-06-14 16:39 - 2017-05-14 20:06 - 01737600 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2017-06-14 16:39 - 2017-05-14 20:06 - 01502000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll
2017-06-14 16:39 - 2017-05-12 19:05 - 00035840 _____ (Adobe Systems) C:\Windows\SysWOW64\atmlib.dll
2017-06-14 16:39 - 2017-05-12 18:16 - 01084928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2017-06-14 16:39 - 2017-05-12 18:13 - 01559552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2017-06-14 16:39 - 2017-05-12 17:51 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2017-06-14 16:39 - 2017-05-12 17:50 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2017-06-14 16:39 - 2017-05-12 17:48 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2017-06-14 16:39 - 2017-05-12 17:47 - 00726528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2017-06-14 16:39 - 2017-05-12 06:10 - 00044032 _____ (Adobe Systems) C:\Windows\system32\atmlib.dll
2017-06-14 16:39 - 2017-05-12 04:58 - 01985536 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
2017-06-14 16:39 - 2017-05-12 04:48 - 01377792 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll
2017-06-14 16:39 - 2017-05-12 04:18 - 03714560 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2017-06-14 16:39 - 2017-05-12 04:11 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2017-06-14 16:39 - 2017-05-12 04:10 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2017-06-14 16:39 - 2017-05-12 04:07 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
2017-06-14 16:39 - 2017-05-12 04:06 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
2017-06-14 16:39 - 2017-05-12 04:04 - 00897024 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
2017-06-14 16:39 - 2017-05-12 04:00 - 02240512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2017-06-14 16:39 - 2017-05-12 01:36 - 22361848 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll
2017-06-14 16:39 - 2017-05-12 01:32 - 19788672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2017-06-14 16:39 - 2017-05-10 20:19 - 00101720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mountmgr.sys
2017-06-14 16:39 - 2017-05-06 18:05 - 01094656 _____ (Microsoft Corporation) C:\Windows\system32\localspl.dll
2017-06-14 16:39 - 2017-05-06 18:04 - 00865792 _____ (Microsoft Corporation) C:\Windows\system32\win32spl.dll
2017-06-14 16:39 - 2017-04-09 22:40 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\winhvr.sys
2017-06-14 16:39 - 2017-04-09 22:39 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbkmclr.sys
2017-06-14 16:39 - 2017-04-09 22:37 - 00129536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\vmbusr.sys
2017-06-14 16:39 - 2017-04-09 21:00 - 00014336 _____ (Microsoft Corporation) C:\Windows\system32\vmbuspiper.dll
2017-06-14 16:39 - 2017-04-06 19:37 - 00445440 _____ (Microsoft Corporation) C:\Windows\system32\certcli.dll
2017-06-14 16:39 - 2017-04-06 19:16 - 00615936 _____ (Microsoft Corporation) C:\Windows\system32\wpd_ci.dll
2017-06-14 16:39 - 2017-04-06 18:50 - 01436672 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll
2017-06-14 16:39 - 2017-04-06 18:46 - 00434688 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll
2017-06-14 16:39 - 2017-04-06 18:46 - 00324096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\certcli.dll
2017-06-14 16:39 - 2017-04-06 18:35 - 01362432 _____ (Microsoft Corporation) C:\Windows\system32\gpsvc.dll
2017-06-14 16:39 - 2017-04-06 18:15 - 00358912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2017-06-14 16:39 - 2017-04-06 17:44 - 00087040 _____ (Microsoft Corporation) C:\Windows\system32\wpdbusenum.dll
2017-06-14 16:39 - 2017-04-02 16:49 - 00186880 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll
2017-06-14 16:39 - 2017-04-02 15:40 - 02013016 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2017-06-14 16:39 - 2016-06-11 18:50 - 00987136 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll
2017-06-14 16:39 - 2016-06-11 18:24 - 00800768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll
2017-06-10 09:16 - 2017-06-10 09:16 - 00013216 _____ C:\Users\Roko\Documents\cc_20170610_091604.reg
2017-06-10 09:15 - 2017-06-10 09:15 - 00067434 _____ C:\Users\Roko\Documents\cc_20170610_091534.reg
2017-06-07 22:57 - 2017-06-07 23:04 - 00000000 ____D C:\Users\Roko\Downloads\The Last King of Scotland (2006)
2017-06-04 09:46 - 2017-06-04 09:53 - 00000000 ____D C:\Users\Roko\Desktop\New folder
2017-06-04 09:00 - 2017-06-04 09:07 - 00007602 _____ C:\Users\Roko\AppData\Local\resmon.resmoncfg
2017-06-04 07:44 - 2017-07-02 22:55 - 00000000 ____D C:\AdwCleaner
2017-06-03 09:13 - 2017-06-03 10:40 - 00000000 ____D C:\Users\Roko\Downloads\codex-rime
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2017-07-02 23:05 - 2017-05-06 20:57 - 00000000 ____D C:\ProgramData\NVIDIA
2017-07-02 23:03 - 2017-05-06 20:54 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1483072306-4082277022-3870291831-1001
2017-07-02 22:58 - 2017-05-07 01:07 - 00000000 ____D C:\Program Files (x86)\Steam
2017-07-02 22:56 - 2013-08-22 16:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2017-07-02 22:55 - 2017-05-06 20:44 - 00000000 ____D C:\Users\Roko
2017-07-02 15:06 - 2013-08-22 17:36 - 00000000 ___HD C:\Windows\system32\GroupPolicy
2017-07-02 14:38 - 2017-05-06 20:55 - 00000000 ____D C:\Users\Roko\AppData\Roaming\uTorrent
2017-07-02 14:03 - 2017-05-06 21:07 - 00000000 ____D C:\Program Files\Opera
2017-07-02 02:09 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\Inf
2017-06-30 23:04 - 2017-05-06 21:07 - 00003832 _____ C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1494097665
2017-06-29 23:53 - 2017-05-06 23:11 - 00003852 _____ C:\Windows\System32\Tasks\NvNodeLauncher_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:11 - 00001432 _____ C:\Users\Public\Desktop\GeForce Experience.lnk
2017-06-29 23:53 - 2017-05-06 23:10 - 00004146 _____ C:\Windows\System32\Tasks\NvDriverUpdateCheckDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003738 _____ C:\Windows\System32\Tasks\NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003738 _____ C:\Windows\System32\Tasks\NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003730 _____ C:\Windows\System32\Tasks\NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003554 _____ C:\Windows\System32\Tasks\NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 23:10 - 00003494 _____ C:\Windows\System32\Tasks\NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}
2017-06-29 23:53 - 2017-05-06 20:57 - 00000000 ____D C:\ProgramData\NVIDIA Corporation
2017-06-29 23:53 - 2017-05-06 20:57 - 00000000 ____D C:\Program Files\NVIDIA Corporation
2017-06-29 23:53 - 2017-05-06 20:57 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation
2017-06-21 09:07 - 2017-05-06 23:11 - 01903224 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap64.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 01755256 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge64.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 01489528 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspcap.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 01317496 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvspbridge.dll
2017-06-21 09:07 - 2017-05-06 23:11 - 00121464 _____ C:\Windows\system32\NvRtmpStreamer64.dll
2017-06-20 22:58 - 2017-05-06 23:10 - 00001951 _____ C:\Windows\NvTelemetryContainerRecovery.bat
2017-06-17 03:31 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\NDF
2017-06-16 21:09 - 2017-05-06 20:48 - 00000000 ____D C:\Users\Roko\AppData\Local\Packages
2017-06-16 21:09 - 2013-08-22 17:36 - 00000000 ___HD C:\Program Files\WindowsApps
2017-06-16 21:09 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\AppReadiness
2017-06-15 23:33 - 2017-05-15 20:24 - 00000000 ____D C:\Windows\Minidump
2017-06-15 09:25 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\rescache
2017-06-15 08:10 - 2013-08-22 16:44 - 00365880 _____ C:\Windows\system32\FNTCACHE.DAT
2017-06-15 00:45 - 2013-08-22 17:36 - 00000000 ___RD C:\Windows\ToastData
2017-06-14 17:01 - 2013-08-22 17:20 - 00000000 ____D C:\Windows\CbsTemp
2017-06-14 17:00 - 2017-05-06 21:13 - 00000000 ____D C:\Windows\system32\MRT
2017-06-14 16:58 - 2017-05-06 21:13 - 133627792 ____C (Microsoft Corporation) C:\Windows\system32\MRT.exe
2017-06-14 16:34 - 2017-05-07 14:49 - 00401408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb.sys
2017-06-14 16:34 - 2017-05-07 14:49 - 00285184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb10.sys
2017-06-14 16:34 - 2017-05-07 14:49 - 00201728 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxsmb20.sys
2017-06-13 21:39 - 2017-05-10 00:17 - 00000980 _____ C:\Users\Roko\Documents\fgfgfgffg.txt
2017-06-13 21:10 - 2017-06-01 19:42 - 00000000 ____D C:\Users\Roko\Desktop\TRIO DIvertimento
2017-06-10 10:20 - 2017-05-06 21:08 - 00000000 ____D C:\Users\Roko\AppData\Local\CrashDumps
2017-06-10 10:18 - 2017-05-06 23:02 - 00000000 ____D C:\Users\Roko\AppData\Local\ElevatedDiagnostics
2017-06-10 10:06 - 2017-05-06 20:46 - 00818732 _____ C:\Windows\system32\PerfStringBackup.INI
2017-06-10 09:27 - 2013-08-22 15:25 - 00262144 ___SH C:\Windows\system32\config\BBI
2017-06-10 09:22 - 2017-05-15 21:51 - 00035328 ___SH C:\Users\Roko\Desktop\Thumbs.db
2017-06-10 09:14 - 2017-05-07 06:36 - 00000000 ____D C:\Windows\Panther
2017-06-10 09:07 - 2017-05-07 05:50 - 00000000 __SHD C:\Users\Roko\AppData\Local\EmieUserList
2017-06-10 09:07 - 2017-05-07 05:50 - 00000000 __SHD C:\Users\Roko\AppData\Local\EmieSiteList
2017-06-10 09:06 - 2017-05-08 22:18 - 00004478 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier
2017-06-10 09:06 - 2017-05-07 22:12 - 00000000 ____D C:\Users\Roko\AppData\Local\Adobe
2017-06-10 09:06 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\SysWOW64\Macromed
2017-06-10 09:06 - 2013-08-22 17:36 - 00000000 ____D C:\Windows\system32\Macromed
2017-06-07 22:51 - 2017-05-06 20:57 - 00001951 _____ C:\Windows\NvContainerRecovery.bat
2017-06-04 09:10 - 2013-08-22 17:36 - 00000000 ____D C:\PerfLogs
2017-06-03 04:31 - 2017-05-09 16:24 - 00835576 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2017-06-03 04:31 - 2017-05-09 16:24 - 00177656 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Files in the root of some directories =======
2017-06-04 09:00 - 2017-06-04 09:07 - 0007602 _____ () C:\Users\Roko\AppData\Local\resmon.resmoncfg
2017-05-25 22:06 - 2017-05-25 22:06 - 0000003 _____ () C:\Users\Roko\AppData\Local\updater.log
2017-05-25 22:06 - 2017-05-25 22:06 - 0000425 _____ () C:\Users\Roko\AppData\Local\UserProducts.xml
Files to move or delete:
====================
C:\Users\Roko\installshield_scm.reg
C:\Users\Roko\scm.reg
Some files in TEMP:
====================
2017-07-02 14:34 - 2017-05-14 20:06 - 1737600 _____ (Microsoft Corporation) C:\Users\Roko\AppData\Local\Temp\dllnt_dump.dll
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2017-06-25 20:27
==================== End of FRST.txt ============================